|
This is a difficult newsletter to write. I’ve been asked about the cybersecurity aspects of political events countless times in the last several years, but this past month has brought up questions I never expected to hear. A client asked me my opinion on AI’s ability to edit the footage of recent killings in Minneapolis. In the spirit of transparency and education, I have included my opinion about that below. If a discussion about that will offend you, this may be a newsletter you want to skip.
Welcome back to the monthly TCE Strategy newsletter! From new AI laws to AI as a hacker to AI as a garbage sorter to AI changing our perception of reality, it’s been yet another wild time in the world of cybersecurity. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.
AI as a hacker
AI is doing a lot of very impressive things, and it is changing both the offensive and defensive sides of cybersecurity. As is true of most new technologies, offensive use is gaining traction more quickly than the defense, which makes sense, as offense (read: cybercriminals) are normally more willing to make mistakes, break things, and learn as they go whereas the organizations defending against the cybercriminals utilize a different tactic. This past month, researchers decided to test AI’s ability to find and exploit vulnerabilities in a network. They set up an AI engine called ARTEMIS and had it compete against 10 professional cybersecurity experts in a network of roughly 8000 computers. The AI engine came in 2nd in the competition. In time, AI is almost certainly going to improve at a much faster rate than humans will.
Takeaways: AI is a tool, and like all tools, they are morally agnostic. Now that AI has reached a level where it can automate many cybersecurity “threat hunting” activities, those that use it will have an advantage, be it offense or defense. Because cybercriminals have much less concern for collateral damage than those of us on defense do (with a few very notable exceptions), AI is going to make cybersecurity issues worse before they get better. Thankfully, AI is not yet inventing net new pathways of cybercriminal attack (although it is doing a great job of finding new vulnerabilities within existing classes of attack), but that too is likely just a matter of time.
AI as a garbage sorter
In less weighty news, a company out of London, UK called Greyparrot is using an AI engine to review video footage of garbage going along a conveyor belt so that it can pick out valuables before they make it into a landfill. Many metals such as aluminum are often thrown away, so the economic and environmental wins of doing a better job recycling these materials are obvious. AI is likely to need a lot of time to develop better skills to tell “good” trash from “bad” trash, but there are so many potential advantages here. Imagine AI finding dangerous substances such as asbestos which needs special handling, or finding chemicals that may leech into drinking water. The possibilities are endless.
Takeaways: Sorting garbage is not a job that many people want to do. While AI likely can’t yet do as good a job of sorting as a human can, it almost certainly will in time. Projects like this need more support. Well done Greyparrot.
AI laws begin to take shape
I’m very excited about the upcoming release of a new book that is a collaboration between myself and several other cybersecurity professionals about how AI and cybersecurity will shape our world. My contribution to the book is an analysis of how AI is changing the legal system in terms of interpreting existing laws, writing new laws, and on laws written about AI. More to come on those. This month, South Korea passed the first comprehensive set of laws on the use of AI. Much of it is common sense (don’t let AI make decisions about nuclear safety for example), but others are more nuanced, such as disclosure requirements to consumers about products / services that use generative AI. The laws themselves are interesting, but they won’t mean much until enforcement actions are taken regarding those laws, and companies have a minimum of a one-year grace period before the laws take effect. Various industries have already voiced concerns that the new laws may hinder innovation, but frankly, I’d really like to see notices that a video I’m watching is AI generated.
Takeaways: I’m glad to see that some sort of guardrails are being raised around ethical use of AI, but laws themselves do not change behavior. Laws, enforcement of those laws, and sufficient penalties for breaking those laws are all needed to change behavior.
AI causes us to question reality
This is the challenging part of the newsletter. Let me preface this by saying that I started TCE Strategy to help keep people safe. I lost my career in 2014 after cybercriminals attacked Target, and when I moved from bonus checks to unemployment checks, it altered my sense of reality. I’m thrilled to say that my career path was changed for the better, but the mission of TCE Strategy has remained unchanged: I want to help keep people safe. Period.
Recent events in Minneapolis have led to the killing of two US Citizens. These events were recorded by smartphones from different angles. I had a client reach out over the weekend to ask my opinion on the validity of the video footage, as the videos themselves and the narrative from the US Federal government seem to have almost nothing in common. That being said, I’m not an expert in law enforcement, and it isn’t appropriate for me to give a professional analysis of those videos and what they mean. My expertise is in cybersecurity, so I’m going to stick to that.
The question that was brought up to me was this: Is it possible that the videos depicting the shootings of Renee Nicole Goode and Alex Pretti could have been altered by AI to depict events differently than they occurred? It’s a reasonable question. There are multiple examples of court cases where altered video evidence was submitted. In the cases of Goode and Pretti, many videos from many sources were posted online very shortly after the shootings took place. In my opinion, it is not possible that AI was used to alter these videos, but the reason is more around logistics than technology. First, the videos have been viewed by literally millions of people and examined by thousands of experts at this point, and they have been found to be authentic by people trained to look for forgeries (in fact, one forged video that came out 3 days after Renee’s shooting was quickly identified as AI-generated). Second, if the videos were altered, they would have all had to have been altered in a very specific way to show consistency between them, and this would have to be done within minutes of the shootings. This would require a lot of coordination, so much so that it would have been impossible without advance notice given to all parties: the people doing the video taping, the ICE officers involved, and the deceased. I can’t imagine a situation where that would have occurred. For those reasons, I believe the video footage of both shootings is authentic.
This newsletter isn’t about politics. While my focus is cybersecurity, my mission is simply to keep people safe. Safe from cybercriminals. Safe from misinformation. Safe from propaganda.
Until next month, please stay safe.
|